THREAT OPS › Threat News › [GHSA] GHSA-8vh3-g2qg-2h2c (critical) — nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
[GHSA] GHSA-8vh3-g2qg-2h2c (critical) — nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
GHSA-8vh3-g2qg-2h2c Severity: critical CVE: CVE-2026-55640
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
## Summary The `POST /webhooks/nextcloud` endpoint has no authentication by default: `WEBHOOK_SECRET` defaults to `None` and is never required by startup validation. When unset, the receiver ac
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-55640cve
Original source: https://github.com/advisories/GHSA-8vh3-g2qg-2h2c